IOC Enrichment
IOC enrichment augments a bare indicator — an IP, domain, or hash — with context such as risk score, confidence, categories, WHOIS, DNS, geolocation, and related infrastructure. Enrichment turns block/allow decisions into informed analyst and automation workflows.
Frequently Asked Questions
What is IOC Enrichment?
IOC enrichment augments a bare indicator — an IP, domain, or hash — with context such as risk score, confidence, categories, WHOIS, DNS, geolocation, and related infrastructure. Enrichment turns block/allow decisions into informed analyst and automation workflows.
How is IOC Enrichment related to IOC (Indicator of Compromise)?
IOC Enrichment and IOC (Indicator of Compromise) are both key concepts in threat intelligence. An indicator of compromise is an indicator supported by evidence of compromise or malicious activity. Security teams use IOCs to detect, contain, and investigate threats; an arbitrary IP address, domain, URL, file hash, or email address is only an observable until evidence supports that promotion.
Related Terms
IOC (Indicator of Compromise)
An indicator of compromise is an indicator supported by evidence of compromise or malicious activity. Security teams use IOCs to detect, contain, and investigate threats; an arbitrary IP address, domain, URL, file hash, or email address is only an observable until evidence supports that promotion.
Confidence Score
A confidence score quantifies how certain a threat intelligence system is that an indicator is malicious, given the evidence. isMalicious weights source signals by reliability, compares agreement and conflicts, and applies time decay to older observations.
Bulk API
A bulk API endpoint accepts multiple indicators in a single request, enabling high-throughput threat intelligence lookups without the latency overhead of individual calls. isMalicious supports batches of up to 10,000 mixed IP, domain, and URL indicators per request.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.